Weaponizing the PaperCut Exploit Chain: How AI Agents Automated 440+ Compromises in Hours
A highly automated cyberattack campaign has weaponized the PaperCut exploit chain to compromise at least 440 PaperCut NG/MF instances across 395 organizations worldwide. Rather than relying on traditional static scripting, the threat actor orchestrated hundreds of concurrent AI agents to manage the entire lifecycle of vulnerability research, exploit development, targeting, and post-exploitation validation.
According to threat intelligence reports published by Blackpoint Cyber and GreyNoise, the campaign represents a significant paradigm shift in offensive security, demonstrating how autonomous agentic workflows can compress the timeline from initial vulnerability disclosure to global exploitation down to mere hours.
The PaperCut Exploit Chain: CVE-2026-81578 and CVE-2026-82078
The campaign centers on the chaining of two distinct vulnerabilities affecting PaperCut NG and PaperCut MF (major versions 24, 25, and 26). When combined, these flaws allow remote, unauthenticated attackers to execute arbitrary code under the security context of the PaperCut server process, which typically runs with local SYSTEM privileges on Windows environments.
The first link in the PaperCut exploit chain is CVE-2026-81578 (CVSS 8.8), an improper access control vulnerability within the web management interface. This flaw allows remote, unauthenticated HTTP requests targeting administrative endpoints to trigger backend operations before the application's access validation checks complete. Attackers leverage this race-like condition to alter system configurations without authenticating.
The second link is CVE-2026-82078 (CVSS 9.4), an unsafe dynamic class-loading vulnerability located in the application's database connection utilities. The PaperCut application instantiates database driver classes based on driver names supplied via configuration files, without validating those classes against an approved allowlist.
To execute the full chain, the attacker performs the following sequence:
- The attacker sends an unauthenticated request exploiting CVE-2026-81578 to modify the application's database driver configuration.
- The attacker configures the driver name to point to a malicious Java class file residing on the application classpath or locally accessible paths.
- The application attempts to initialize the database connection utility, triggering CVE-2026-82078 to dynamically load and execute the arbitrary Java bytecode as
SYSTEM.
The following log snippet, highlighted in advisory documentation from eSentire, indicates failed or manipulated attempts to load database drivers during exploitation:
ERROR No suitable driver found for jdbc:no:x
ERROR DatabaseUtils - Database error looking up cardID: VALUES CASTInside the AI Agentic Workflow Architecture
What distinguishes this campaign from historical exploitation waves is the underlying orchestration infrastructure. Analysis of the attacker's command-and-control (C2) infrastructure at IP address 45.142.193[.]132 revealed an active development environment utilizing hundreds of autonomous AI agents working in parallel.
The threat actor utilized OpenAI Codex as an execution harness alongside a DeepSeek model to perform iterative code generation, debugging, and target scanning. The agentic system relied on two key open-source orchestration components:
- Hindsight: An open-source persistent memory layer designed to preserve context across agent sessions. State files captured completed tasks, blockers, immediate hypotheses, and code changes, allowing agents to resume interrupted workflows without losing progress.
- AionUI: A unified graphical workspace used to monitor, coordinate, and execute multiple AI agents concurrently.
This setup enabled a highly structured targeting pipeline. Rather than executing simple, noisy IP sweeps, the AI agents operated a multi-stage funnel. Python-based scanning scripts utilizing up to 80 concurrent workers checked target reachability over HTTP/HTTPS. The pipeline merged multiple target lists, geolocated candidates, and applied a strict country exclusion list (attempting to avoid 28 countries, including Russia, China, and Iran).
Crucially, the agents incorporated a dynamic feedback loop. When an exploitation attempt failed, the agent analyzed the returned error, modified the exploit code to account for target-specific environmental differences (such as operating system or Java version), and initiated repeated retry waves (up to 100 rounds) while preserving successful results.
According to The Hacker News, GreyNoise observed the attacker progress from an empty workspace to achieving their first real-world remote code execution in under four hours. Once the automated campaign was fully launched, the agents compromised 11 distinct organizations within a 26-second window.
Mitigation, Patching, and Post-Exploitation Hunting
In response to active exploitation, PaperCut issued a series of emergency patches, culminating in Emergency Patch Release 3 on September 1, 2026. This release supersedes previous emergency builds and addresses regressions, such as broken SAML login flows and legacy database driver compatibility issues introduced in earlier hotfixes.
1. Apply the Security Patches
Administrators must immediately upgrade all PaperCut NG and PaperCut MF instances to the appropriate maintenance release. It is critical to note that site servers and secondary/print servers must be patched in tandem with the primary application servers, as detailed in the runZero vulnerability index.
| Major Version Branch | Patched Version (Release 3 / Maintenance) |
|---|---|
| PaperCut NG/MF 26.x | 26.0.5 |
| PaperCut NG/MF 25.x | 25.0.13 |
| PaperCut NG/MF 24.x | 24.1.10 |
| PaperCut NG/MF 23.x and older | Unsupported. Upgrade to a supported branch first. |
2. Restrict Network Exposure
If patching cannot be performed immediately, restrict external access to the PaperCut web management ports (TCP 9191 and 9192). Block internet-facing access entirely or restrict traffic to trusted administrative IP addresses via firewalls or access control lists (ACLs).
3. Hunt for Post-Exploitation Activity
Because the attackers achieved domain administrator access in at least 12 confirmed cases—sometimes within minutes of initial access—organizations must hunt for indicators of compromise (IoCs) on their PaperCut hosts. Security teams should execute the following checks:
- Process Monitoring: Inspect all child processes spawned by the PaperCut application binary (
pc-app.exe). Be alert for shell executions (cmd.exe,powershell.exe) or system discovery utilities. - File Integrity: Scan the application directory for unauthorized Java
.classpayload drops. The campaign frequently dropped files namedUdydn.classandUdydn Moo97.classto establish persistence. - Credential Harvesting: Look for evidence of registry hive dumping (such as copying
SAM,SECURITY, orSYSTEMhives) and the execution of offensive tools like Mimikatz, SharpHound, Certipy, Rubeus, or Impacket. - Log Analysis: Look for gaps in PaperCut server logs, truncated log files, or unexpected administrative configuration changes made prior to patching.
Frequently asked questions
What is the PaperCut exploit chain?
The PaperCut exploit chain combines CVE-2026-81578 (authentication bypass via improper access control) and CVE-2026-82078 (unsafe dynamic class loading) to achieve pre-authentication remote code execution (RCE) on PaperCut NG/MF servers.
Which versions of PaperCut are vulnerable to these exploits?
PaperCut NG and PaperCut MF major versions 24, 25, and 26 are vulnerable. The flaws are patched in versions 24.1.10, 25.0.13, and 26.0.5.
How did attackers use AI agents in this campaign?
Attackers used OpenAI Codex and a DeepSeek model orchestrated via Hindsight and AionUI to handle vulnerability research, code testing, target filtering, and iterative error debugging across hundreds of live targets.
What post-exploitation behavior should defenders hunt for?
Defenders should monitor suspicious child processes spawned by pc-app.exe, look for dynamic Java .class files like Udydn.class, and check for Windows registry hive collection or Active Directory querying.
Sources
- Death by a Thousand PaperCuts: AI-Driven Exploitation at Scale — Blackpoint Cyber
- PaperCut Discloses Zero-Day Vulnerabilities (CVE-2026-82078 and CVE-2026-81578) — eSentire
- PaperCut Attacker Uses Hundreds of AI Agents to Compromise 440+ Instances — The Hacker News
- PaperCut Software vulns: CVE-2026-81578, CVE-2026-82078 — runZero
